GRC & Audit Support · Lesson 4 of 8
From requirements to controls
A requirement states an expected outcome. A control is an action or safeguard intended to support that outcome. Evidence helps a reviewer assess whether it operates.
Trace the claim to proof
Illustrative access-review requirement.
- Requirement
Remove inappropriate access.
- Control
Managers review permissions; owners implement approved removals.
- Evidence
Review decisions plus removal records and verification.
Read the visualWhat is missing if you only have a completed review spreadsheet?
Evidence that required access changes were implemented and verified.
Define the expected result
Use an applicable requirement and a clear scope. Do not assume a framework automatically creates a legal obligation.
Describe the control
State who does what, when, and for which systems. Broad statements such as we review access are hard to test.
Plan a test
Identify what evidence could demonstrate operation during the period. A written policy alone does not establish execution.
Put it in context
Requirement: inappropriate access is removed. Control: managers review listed permissions quarterly and owners implement approved removals. Evidence includes the review and removal records.
Connect requirement, control, and evidence without treating them as interchangeable.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.